Threat actors have been targeting poorly secured, internet-exposed Microsoft SQL Server instances to deliver Mimic and Trigona ransomware, using brute-force or weak credentials and, in some cases, xp_cmdshell for command execution. Researchers reported that one actor used the SQL Server Bulk Copy Program (BCP) utility to rebuild malware from database contents onto disk, while other intrusions relied on PowerShell download cradles, mounted SMB shares, and remote access tools including AnyDesk. In multiple cases, the attackers established persistence, created administrator accounts, enabled credential theft opportunities such as the WDigest\UseLogonCredential registry setting, and deployed tooling including Mimikatz, PsExec, Advanced Port Scanner, Defender Control, and SDelete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
AhnLab assessed that the early-January Mimic incident and mid-January Trigona incident were likely conducted by the same threat actor. The linkage was based on shared MSSQL targeting, identical BCP-based installation, reused strings and paths, and overlapping supporting malware.
In mid-January 2024, AhnLab identified similar attacks in which the same installation method was used but Trigona ransomware was deployed instead of Mimic. The activity again targeted poorly managed, externally exposed MS-SQL servers.
AhnLab ASEC first discovered a case in early January 2024 where attackers used the MS-SQL Bulk Copy Program utility to reconstruct and install Mimic ransomware from database contents onto disk. The attack targeted a poorly managed, externally exposed MS-SQL server.
Trend Micro said a new 64-bit Windows version of Trigona was encountered in June 2023. This variant added command-line arguments such as /sleep and /debug.
Trend Micro reported that a Linux version of Trigona was found in May 2023. The Linux binary shared similarities with the Windows counterpart and accepted command-line arguments for execution.
AhnLab previously reported in April 2023 that Trigona targeted poorly managed MS-SQL servers. Trend Micro likewise noted that by April 2023 Trigona had begun targeting compromised MSSQL servers using stolen or brute-forced credentials.
AhnLab cited an Arete report from February 2023 stating that Trigona exploited the ManageEngine vulnerability CVE-2021-40539 for initial access. Trend Micro also noted this exploitation path in its overview.
Trend Micro said the Trigona ransomware family became active around late October 2022. The operators subsequently continued updating the malware across multiple variants.
AhnLab stated that Mimic ransomware was first identified in June 2022. The family is known for using the Everything file-search tool and borrowing some features from leaked Conti source code.
Trend Micro reported that samples of the Trigona ransomware family existed as early as June 2022, predating its broader observed activity. AhnLab also described Trigona as active since at least June 2022.
Securonix reported an ongoing campaign it tracks as RE#TURGENCE in which likely Turkish, financially motivated actors brute-force exposed MSSQL servers, abuse xp_cmdshell, and either sell access or deploy Mimic ransomware. In the observed intrusion, the attackers used PowerShell download cradles, an obfuscated Cobalt Strike beacon, AnyDesk, Mimikatz, Advanced Port Scanner, and PsExec before manually deploying Mimic across the domain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securonix.com
Open sourceasec.ahnlab.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.